← Back to results

Product Security Engineer

Join Bugcrowd as a Product Security Engineer to drive security outcomes and partner closely with engineering in a fully remote role.

Location
Costa Rica
Compensation
Not disclosed
Level
mid
Type
full time · Remote

Posted by employer 1 day ago

First seen on Joblaze 1 hour ago

Last verified on the company career page 1 hour ago

Apply at Bugcrowd → Save job Scanned from bugcrowd.com

What you'll build

  • Refine architecture and validate new features
  • Contribute to secure defaults and libraries
  • Tune security tooling to reduce noise
  • Lead cross-functional product security projects
  • Build systems based on incentives and accountability

Must have

  • 3+ years of experience in product security
  • Can review code and build security tooling in at least one modern programming language
  • Hands-on experience with core application security practices
  • Demonstrated ability to manage projects and influence cross-functional partners
  • Bachelor's degree in engineering, computer science or relevant field

Nice to have

  • Previous experience with Bug Bounty or vulnerability disclosure programs
  • A background in building secure-by-default internal libraries
  • Hands-on experience securing cloud-native platforms
  • Experience working within a fast-paced, high-growth security or SaaS company

AI in the day-to-day

We combine the power of humans and AI to preempt attack paths and prevent breaches.

Requirements

Experience
3+ years
Education
Bachelor's degree

Not disclosed in this posting: compensation, visa sponsorship.

Joblaze summary

In this role, the Product Security Engineer at Bugcrowd is responsible for integrating security into the development process, collaborating closely with engineering teams to enhance architecture and validate new features. The position requires proficiency in modern programming languages and hands-on experience with application security practices, including threat modeling and automated testing. Ideal candidates have a background in product security or secure software development, with a focus on driving measurable security outcomes. Bugcrowd fosters a collaborative environment, emphasizing a culture where security is a shared responsibility.

Joblaze insights

  • Listed today — first seen on Joblaze October 3, 2026. Last confirmed on Bugcrowd's careers page October 3, 2026.

Quick facts

Is the Product Security Engineer role remote?
Yes — Bugcrowd lists this as a fully remote position.
How much experience is required?
At least 3 years of relevant experience for this Product Security Engineer role.
What's the tech stack?
Joblaze extracted these technologies from the posting: AWS, DAST, Docker, GCP, Go, Java.
What seniority level is this role?
Bugcrowd targets mid-level candidates for this position.
Is this full-time or contract?
Full-time for this Product Security Engineer role at Bugcrowd.

From the original posting

Founded in 2012, Bugcrowd is the preemptive security platform that unifies exposure discovery and assessment, offensive testing, and intelligence shaped by AI and human insight to help organizations avoid, discover, and validate real-world risk. Bugcrowd helps security teams move faster by identifying the exposures that matter most so they can act first and stay ahead of attackers. By combining the power of humans and AI, teams can preempt attack paths and prevent breaches. Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst, Rally Ventures, Costanoa Ventures, and others. Visit www.bugcrowd.com.

Job Summary

If you like owning problems end to end, making security a default property of everything we build, and working closely with engineering, we want to meet you. Bugcrowd is looking for security engineers who move beyond standard tooling and drive measurable security outcomes our customers can rely on. You will help us shape a culture where security helps others succeed, not just points out problems.

Essential Duties and Responsibilities

  • Partner Closely with Engineering: Refine architecture, validate new features, and drive security investment while prioritizing engineering velocity
  • Build Security Paved Roads: Contribute to the secure defaults, libraries, and "paved roads" that systematically eradicate entire classes of vulnerabilities rather than fixing bugs one by one
  • Create Feedback Loops: Tune security tooling such as SAST, DAST, SCA, and secret scanning to reduce noise and focus on what matters
  • Be our Best Customer: Ensure our bug bounty program can be a model for other customers. Experiment with new ways to leverage the creativity of the crowd. Provide feedback on new platform features to engineering and product
  • Own Projects End to End: Lead cross-functional product security projects from scoping through delivery, influencing product and engineering roadmaps and clearly communicating risk to both technical and non-technical stakeholders
  • Amplify our Impact: Use code and automation as a lever to scale coverage and eliminate repetitive work. Build systems based on incentives and accountability rather than just bureaucratic process

Education, Experience, Knowledge, Skills, and Abilities

  • 3+ years of experience in product security, application security, or secure software development
  • Can review code, automate tasks, and build security tooling in at least one modern programming language (e.g., Python, Go, Ruby, Java)
  • Hands-on experience with core application security practices — threat modeling, secure code review, and automated testing (SAST, DAST, SCA) — and a solid grasp of common vulnerability classes (e.g., OWASP Top 10)
  • Demonstrated ability to manage projects and influence cross-functional partners across engineering, DevOps, and product.
  • Bachelor's degree in engineering, computer science or relevant field, or equivalent practical experience

Bonus Points (Preferred but not required)

  • Previous experience with Bug Bounty or vulnerability disclosure programs
  • A background in building "paved roads" or secure-by-default internal libraries to eliminate entire classes of vulnerabilities
  • Hands-on experience securing cloud-native platforms and Infrastructure as Code (e.g., Terraform, AWS, GCP, Kubernetes, Docker)
  • Experience working within a fast-paced, high-growth security or SaaS company
  • Sitting and / or standing - Must be able to remain in a stationary position 50% of the time
  • Carrying and / or lifting - Must be able to carry / move laptop as needed throughout the work day.
  • Environment - remote, work-from-home 100% of the time

ADA Statement:

Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ada@bugcrowd.com.

Background checks may include Social Security verification, prior employment verification, personal and professional references, education verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required by law.

Equal Opportunity Employer:

Bugcrowd is an Equal Opportunity and Affirmative Action employer. All qualified applicants will receive consideration for employment without regards to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Culture

Equal Employment Opportunity:

Bugcrowd is EOE, Disability/Age Employer.

Apply at: https://www.bugcrowd.com/about/careers/

Standard company text repeated across Bugcrowd's postings is omitted here.

Similar positions

Bugcrowd
Product Marketing Manager
Bugcrowd · Remote - US
Bugcrowd
Horizon3.ai
Cogent Security
Solutions Engineer (US West)
Cogent Security · Remote, US